US2023179630A1PendingUtilityA1

Uncheatable federated learning

Assignee: CISCO TECH INCPriority: Dec 3, 2021Filed: Dec 3, 2021Published: Jun 8, 2023
Est. expiryDec 3, 2041(~15.3 yrs left)· nominal 20-yr term from priority
G06N 20/20H04L 63/1491G06N 20/00G06N 3/08G06N 3/045G06N 3/084
55
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

In one embodiment, a device identifies a plurality of nodes of a distributed or federated learning system. The device receives model training results from the plurality of nodes. The device determines, based in part on the model training results or information about the plurality of nodes, whether a particular node or subset of nodes in the plurality of nodes provided fraudulent model training results. The device initiates a corrective measure with respect to the particular node or subset of nodes, based on a determination that the particular node or subset of nodes provided fraudulent model training results, in accordance with a policy.

Claims

exact text as granted — not AI-modified
1 . A method comprising:
 identifying, by a device, a plurality of nodes of a distributed or federated learning system;   receiving, at the device, model training results from the plurality of nodes;   determining, based in part on the model training results or information about the plurality of nodes, whether a particular node or subset of nodes in the plurality of nodes provided fraudulent model training results; and   initiating, by the device, a corrective measure with respect to the particular node or subset of nodes, based on a determination that the particular node or subset of nodes provided fraudulent model training results, in accordance with a policy.   
     
     
         2 . The method as in  claim 1 , wherein the plurality of nodes each train a machine learning model using local training data, to generate the model training results. 
     
     
         3 . The method as in  claim 1 , wherein nodes in the plurality of nodes are geographically distributed. 
     
     
         4 . The method as in  claim 1 , wherein the corrective measure entails blocking the particular node or subset of nodes from performing further model training in the distributed or federated learning system. 
     
     
         5 . The method as in  claim 1 , further comprising:
 testing the particular node or subset of nodes for fraudulent model training results, based on a likelihood of it supplying fraudulent model training results.   
     
     
         6 . The method as in  claim 1 , wherein determining whether the particular node or subset of nodes in the plurality of nodes provided fraudulent model training results comprise:
 sending a honeypot machine learning model to the particular node or subset of nodes on which it is supposed to generate its model training results, wherein the honeypot machine learning model includes one or more neurons that should not be updated by the particular node or subset of nodes during model training.   
     
     
         7 . The method as in  claim 1 , wherein determining whether the particular node or subset of nodes in the plurality of nodes provided fraudulent model training results comprises:
 sending incorrect model weights to the particular node or subset of nodes for model training, to assess how the particular node or subset of nodes responds.   
     
     
         8 . The method as in  claim 1 , wherein determining whether the particular node or subset of nodes in the plurality of nodes provided fraudulent model training results comprises:
 comparing the model training results of the particular node or subset of nodes to those of one or more other nodes in the plurality of nodes.   
     
     
         9 . The method as in  claim 1 , wherein the corrective measure comprises rolling back a machine learning model trained based in part on the model training results from the particular node or subset of nodes. 
     
     
         10 . The method as in  claim 1 , further comprising:
 aggregating at least a portion of the model training results into an aggregated machine learning model.   
     
     
         11 . An apparatus, comprising:
 one or more network interfaces;   a processor coupled to the one or more network interfaces and configured to execute one or more processes; and   a memory configured to store a process that is executable by the processor, the process when executed configured to:
 identify a plurality of nodes of a distributed or federated learning system; 
 receive model training results from the plurality of nodes; 
 determine, based in part on the model training results or information about the plurality of nodes, whether a particular node or subset of nodes in the plurality of nodes provided fraudulent model training results; and 
 initiate a corrective measure with respect to the particular node or subset of nodes, based on a determination that the particular node or subset of nodes provided fraudulent model training results, in accordance with a policy. 
   
     
     
         12 . The apparatus as in  claim 11 , wherein the plurality of nodes each train a machine learning model using local training data, to generate the model training results. 
     
     
         13 . The apparatus as in  claim 11 , wherein nodes in the plurality of nodes are geographically distributed. 
     
     
         14 . The apparatus as in  claim 11 , wherein the corrective measure entails blocking the particular node or subset of nodes from performing further model training in the distributed or federated learning system. 
     
     
         15 . The apparatus as in  claim 11 , wherein the process when executed is further configured to:
 test the particular node or subset of nodes for fraudulent model training results, based on a likelihood of it supplying fraudulent model training results.   
     
     
         16 . The apparatus as in  claim 11 , wherein the apparatus determines whether the particular node or subset of nodes in the plurality of nodes provided fraudulent model training results by:
 sending a honeypot machine learning model to the particular node or subset of nodes on which it is supposed to generate its model training results, wherein the honeypot machine learning model includes one or more neurons that should not be updated by the particular node or subset of nodes during model training.   
     
     
         17 . The apparatus as in  claim 11 , wherein the apparatus determines whether the particular node or subset of nodes in the plurality of nodes provided fraudulent model training results by:
 sending incorrect model weights to the particular node or subset of nodes for model training, to assess how the particular node or subset of nodes responds.   
     
     
         18 . The apparatus as in  claim 11 , wherein the apparatus determines whether the particular node or subset of nodes in the plurality of nodes provided fraudulent model training results by:
 comparing the model training results of the particular node or subset of nodes to those of one or more other nodes in the plurality of nodes.   
     
     
         19 . The apparatus as in  claim 11 , wherein the corrective measure comprises rolling back a machine learning model trained based in part on the model training results from the particular node or subset of nodes. 
     
     
         20 . A tangible, non-transitory, computer-readable medium storing program instructions that cause a device to execute a process comprising:
 identifying, by the device, a plurality of nodes of a distributed or federated learning system;   receiving, at the device, model training results from the plurality of nodes;   determining, based in part on the model training results or information about the plurality of nodes, whether a particular node or subset of nodes in the plurality of nodes provided fraudulent model training results; and   initiating, by the device, a corrective measure with respect to the particular node or subset of nodes, based on a determination that the particular node or subset of nodes provided fraudulent model training results, in accordance with a policy.

Join the waitlist — get patent alerts

Track US2023179630A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.